SQL Injection Vulnerability in Featured Image from URL Plugin for WordPress
CVE-2025-10036
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 September 2025
What is CVE-2025-10036?
The Featured Image from URL plugin for WordPress is vulnerable to SQL Injection through the get_all_urls() function in all versions up to 5.2.7. This vulnerability arises due to inadequate escaping of user-supplied parameters and a lack of proper preparation in the SQL queries. Authenticated attackers with Administrator-level access can exploit this weakness to inject additional SQL commands into existing queries, potentially allowing them to retrieve sensitive information from the database. Users of this plugin should take immediate action to secure their installations.
Affected Version(s)
Featured Image from URL (FIFU) * <= 5.2.7